Executive brief
Windows Virtualization-Based Security (VBS) is a security feature that uses hardware virtualization to create isolated environments for protecting sensitive system components. An out-of-bounds read vulnerability in VBS Enclave allows an authorized local attacker to read memory contents that should not be accessible, potentially disclosing sensitive information such as encryption keys or other protected data.
Technical details
This vulnerability is an out-of-bounds read in the Windows Virtualization-Based Security Enclave component. An authenticated local attacker can exploit this flaw to read memory beyond the intended boundaries of a buffer, allowing information disclosure. The attack requires local access and authorization on the target system. The vulnerability does not provide remote code execution or privilege escalation, but enables disclosure of sensitive information that may be used in further attacks. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed